LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Containers
User Name
Password
Linux - Containers This forum is for the discussion of all topics relating to Linux containers. Docker, LXC, LXD, runC, containerd, CoreOS, Kubernetes, Mesos, rkt, and all other Linux container platforms are welcome.

Notices


Reply
  Search this Thread
Old 10-02-2019, 06:21 AM   #1
emon_lq
LQ Newbie
 
Registered: Feb 2016
Posts: 13

Rep: Reputation: Disabled
Question Let'sEncrypt on Kubernetes


Hi everyone

I am trying to setup Let'sEncrypt on our on-premise Kubernetes cluster.

Although I am new to SSL certificates & Let'sEncrypt

I have been gathering basic understanding of the following :-

Private/Public key pairs
Certificate Authority
Certificate Signing Requests.
X.509 Certificate types
Domain Validated certificates (DV)
Organization Validated certificate (OV)
Extended Validation certificates (EV)
Using opessl to manipulate/create files like CRT CER KEY (PEM DER)

I have come across a lot of step by step guides on how to deploy cert-manager

What I can't understand Is how they never submit a CSR and pass the validation challenge from Let'sEncrypt??!!

Their deployment just works!!

I have never used Let'sEncrypt, but I have wildcard certificate for my domain from a different RootCA; do I not have to submit CSR to Let'sEncrypt??

Is there something that I am not getting/misunderstanding??

Thanks in advance
Emon

Last edited by emon_lq; 10-02-2019 at 06:25 AM.
 
Old 10-02-2019, 11:51 PM   #2
berndbausch
LQ Addict
 
Registered: Nov 2013
Location: Tokyo
Distribution: Mostly Ubuntu and Centos
Posts: 6,316

Rep: Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002
It's done automatically:
Quote:
The objective of Let’s Encrypt and the ACME protocol is to make it possible to set up an HTTPS server and have it automatically obtain a browser-trusted certificate, without any human intervention. This is accomplished by running a certificate management agent on the web server.
(my highlighting)
 
Old 10-14-2019, 01:41 AM   #3
emon_lq
LQ Newbie
 
Registered: Feb 2016
Posts: 13

Original Poster
Rep: Reputation: Disabled
Talking

Quote:
Originally Posted by berndbausch View Post
It's done automatically:

(my highlighting)

Hi berndbausch

Sorry for the late reply.

After further studying I realized that I was misunderstanding a key concept.


I need to have an actual domain name pointing to my IP!!


This is so embarrassing..,
I can't believe I actually missed that!

Anyways
Thanks Guys

Last edited by emon_lq; 10-14-2019 at 01:42 AM.
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Let's Automate Let's Encrypt LXer Syndicated Linux News 0 11-01-2016 06:51 AM
LXer: Kubernetes container tech hits v1.0. Is that a Tectonic shift I feel? LXer Syndicated Linux News 0 07-21-2015 11:42 PM
LXer: CoreOS is bringing Google's Kubernetes to the enterprise LXer Syndicated Linux News 0 04-06-2015 08:30 PM
"Let it Snow, Let it Snow" .. and the Google That Cried "Wolf" sundialsvcs General 7 02-11-2014 07:59 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Containers

All times are GMT -5. The time now is 04:36 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration